Beatrice provides the booking and billing platform that UK hair, barbering, nails, beauty, lashes and brows, waxing, spray tan, makeup, massage, personal training, tattoo, piercing, permanent makeup, electrolysis and laser businesses use to run their bookings, payments and client messages. This notice explains what personal data we handle, why, and the rights you have under the UK GDPR and the Data Protection Act 2018.
Who we are
Beatrice is a trading name of
Preson Limited, a company registered in England and Wales (company number
17477430), registered office
6 Riverside Court, Croft, Leicester, England, LE9 3HG. Preson Limited also operates Pretty Pooches, our sister platform, on the same core. We are registered with the UK Information Commissioner's Office (ICO) under registration number
ZC256320. Our data-protection contact is
Lewis Preson, Director; for anything in this notice, write to
hello@heybeatrice.com.
Controller and processor — the two roles
We handle data in two distinct roles, and which one applies changes your rights.
We are the controller of the data about you as a business owner: the account you create here, what you tell us about your business, how you use the product, and what you pay us.
You are the controller of your clients' data — their names, contact details, appointment history, notes and any intake or consent answers. We are your
processor for that data: we hold it and act on it to run the service for you, on your instructions. Those instructions are set out in our
Data Processing Agreement.
If you only joined the waitlist
The waitlist form on our home page collects your
email address and, if you give it, your
name. We use it for one thing: to tell you when early access opens in your area, and to answer you if you write back. The lawful basis is our legitimate interest in contacting businesses who asked to hear from us. Reply to any message asking to come off the list, or email
hello@heybeatrice.com, and we delete the record. We do not sell it and we do not pass it on for anyone else's marketing.
Operator data we collect (we are the controller)
Your name, business name, email address, phone number where you give it, your business address and trading location, the trade you selected, your local-authority registration details where your trade requires them, your plan and billing records, sign-in tokens and session data, support correspondence, and product-usage analytics. We never see or store your card number — Stripe does (below).
Client data we process on your behalf (you are the controller)
Your clients' names, email addresses and phone numbers; their addresses and location where you travel to them; their appointment history, your notes, reminder preferences and any photos attached to an appointment; and — where you use them — the answers to your intake, consultation, patch-test and consent forms.
Health information in your clients' records
Several of the trades on Beatrice ask clients about their health before treatment can go ahead: allergies, medications, skin conditions, pregnancy, patch-test outcomes, and informed consent for procedures such as laser, tattooing, piercing, electrolysis and permanent makeup.
That is
special category data under Article 9 of the UK GDPR.
You are the controller of it; we hold it for you and never use it for our own purposes. It is stored against the client's appointment and is visible only to your business.
Because you are the controller, the Article 9(2) condition you rely on for collecting it, and how long you keep treatment and consent records, are
your determinations — and local-authority licence conditions for tattoo, piercing, permanent makeup, electrolysis and laser can require those records to be kept for longer than the 7 years stated below. We will not delete a record you are required to keep without telling you; our commitments for this data are set out in section 4a of our
Data Processing Agreement.
Local-authority registration details
For tattoo, piercing, permanent makeup and electrolysis — and for laser where your council requires it — we collect the council you are registered with, your registration number, whether your premises are registered, and optionally a copy of your certificate. We record the date you confirmed it.
This is a self-declaration we store and timestamp. There is no national register to check it against, so we never describe it as verified, and neither should anyone reading it.
Payments — card data never touches us
Card payments, deposits and payouts run through Stripe. Card numbers are entered directly into Stripe's systems; neither Beatrice nor your business ever sees or stores them. We collect client payments as your commercial agent: Stripe takes each payment on our platform account and transfers it, less our fee, to your own connected Stripe account. We keep the payment references, amounts and statuses we need to reconcile bookings, payouts, refunds and disputes.
Lawful bases (data we control)
Contract — running your account and providing the product you signed up for. Legitimate interests — keeping the service secure, preventing fraud, improving the product, and contacting businesses who asked to hear from us. Legal obligation — tax, accounting and anti-money-laundering records. Consent — optional analytics cookies and any marketing you opt into, which you can withdraw at any time.
Sub-processors
We engage a small set of vetted sub-processors to deliver the service. Each is bound by data-protection terms and processes data only to provide its function. The current list:| Sub-processor | Purpose | Region |
|---|
| Stripe | Card payments, deposits, payouts (Connect) and plan billing | UK / EU / US |
| Amazon Web Services (RDS, S3, SES, CloudFront) | Hosting, database, file storage, transactional email (SES) and our public-asset CDN | EU (eu-west-1, Ireland); CloudFront edge is global |
| Amazon Bedrock (AWS) | AI drafting assistance for our own outreach messages and, where enabled, in-product suggestions; prompts are not used to train the underlying models | EU (eu-west-1) |
| Twilio | SMS sign-in codes, booking reminders and notifications | UK / EU / US |
| Meta — WhatsApp Cloud API | WhatsApp messaging and sign-in codes (where enabled — feature-flagged off by default) | EU / US |
| postcodes.io | Keyless UK postcode geocoding for travel planning (postcodes only — no names or contact details) | UK |
| Google Maps Platform | Travel-time (Distance Matrix) and geocoding, only where a business enables it with its own key | EU / US |
| Google Places | Finding businesses for our own outreach (search terms and area only — no customer or operator account data) | EU / US |
| Push notifications — Apple (APNs), Google (FCM), Expo | Delivering push notifications to the mobile apps (device token + notification payload), where enabled | US |
| Umami (self-hosted) | Cookieless product analytics — page views and named funnel events with no personal identifiers, on our own servers; nothing is shared with an analytics vendor | Our own AWS infrastructure (eu-west-1) |
| PostHog | Optional product analytics — funnels, heatmaps and session replay (replay masks all form input by default). Not currently active; loads only after analytics consent. | EU (eu.i.posthog.com) |
| Sentry | Error monitoring and diagnostics for the websites, apps and API (error reports carry technical details of the request that failed) | EU / US |
| Entri | Searching for and buying a new web domain, only if a business buys one through us (not currently active; connecting a domain a business already owns does not use Entri) | US |
| Google Business Profile | Posting updates and reading reviews on a business's Google Business Profile, only where the business connects it | EU / US |
| Meta — Facebook and Instagram | Posting to a business's Facebook and Instagram accounts, only where the business connects them | EU / US |
| TikTok | Posting to a business's TikTok account, only where the business connects it (not yet available) | US / EU |
We give operators advance notice of any new or replacement sub-processor so an objection can be raised, as set out in our DPA. International transfers
Our primary hosting, client-data storage and transactional email run in the EU (AWS region eu-west-1, Ireland), which the UK recognises as adequate. Some sub-processors — Stripe, Twilio, Google and Meta among them — may process limited personal data outside the UK and EU. Where they do, the transfer is protected by an appropriate safeguard: UK adequacy regulations, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses.
Retention
We keep operator account data while your account is active and for a reasonable period afterwards to meet legal, tax and dispute obligations. Booking records are stripped of personal details and retained for around 7 years to satisfy UK tax and dispute-resolution requirements. When a client deletes their account, it closes at once and can be restored by signing in again within 30 days; after that their identity (name, contact details, address, sign-ins, saved card reference and photos) is erased, while each business keeps its own records of their appointments, payments, consent and patch-test records. Sign-in tokens are kept only while valid; notification logs are kept for delivery troubleshooting and usage metering. Waitlist records are deleted on request, and in any case when the waitlist closes. When a business deletes its account, any client accounts that exist only because that business imported them are erased along with it.
Our database is backed up automatically, encrypted, and each backup is kept for 35 days. Data that has been deleted or erased can therefore remain in those backups for up to 35 days before it is gone for good. We never restore a backup except to recover from a disaster.
Your rights
Under UK data-protection law you have the right to access a copy of your data, correct it, erase it, restrict or object to its processing, and take it elsewhere. Operators can export their own data from the back office at any time. If your request is about data a
business holds about you as its client, that business is the controller — ask them, and we will help them answer. Email
hello@heybeatrice.com for anything we control.
Cookies
We set the cookies needed to sign you in and keep the site secure. Analytics cookies (PostHog) load only after you accept them, and you can change your mind at any time.
Complaints
If we can't resolve a concern, you can complain to the UK Information Commissioner's Office at
ico.org.uk or on 0303 123 1113. We'd appreciate the chance to put things right first.